CVE-2015-5989: Zyxel GS1900-10hp Firmware

Critical severity, CVSS 9.8. EPSS: 2.8% chance of exploitation in the next 30 days.

Belkin F9K1102 2 devices with firmware 2.10.17 rely on client-side JavaScript code for authorization, which allows remote attackers to obtain administrative privileges via certain changes to LockStatus and Login_Success values.

Affected products

  • Zyxel GS1900-10hp Firmware: before 2.50\(aazi.0\)c0 (fixed in 2.50\(aazi.0\)c0)

Published 2015-12-31. Last modified 2026-06-17.